CVE-2021-37136
Published on: 10/19/2021 12:00:00 AM UTC
Last Modified on: 02/24/2023 05:00:00 PM UTC
Certain versions of Tinkerpop from Apache contain the following vulnerability:
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
- CVE-2021-37136 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
The Netty project - Netty version < 4.1.68Final
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Related QID Numbers
- 181469 Debian Security Update for netty (DLA 3268-1)
- 181471 Debian Security Update for netty (DSA 5316-1)
- 240458 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 7 (RHSA-2022:4918)
- 240459 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 8 (RHSA-2022:4919)
- 240925 Red Hat Update for Satellite 6.12 (RHSA-2022:8506)
- 376257 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUJAN2022)
- 960485 Rocky Linux Security Update for Satellite (RLSA-2022:8506)
- 980258 Java (maven) Security Update for io.netty:netty-codec (GHSA-grg4-wf29-r9vv)
Known Affected Configurations (CPE V2.3)
- cpe:2.3:a:apache:tinkerpop:3.5.0:*:*:*:*:*:*:*:
- cpe:2.3:a:apache:tinkerpop:3.5.1:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12:0.0.5.0:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.10.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_instant_messaging_server:8.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:helidon:1.4.10:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:helidon:2.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
#zookeeper: "CVE-2021-37136/37137" ift.tt/3C6WCtK | 2021-09-13 01:58:37 |
![]() |
#zookeeper: "Re: CVE-2021-37136/37137" ift.tt/3lfYVUt | 2021-09-13 04:58:33 |
![]() |
CVE-2021-37136 : The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompress… twitter.com/i/web/status/1… | 2021-10-19 14:44:50 |